Asymmetric denial of service In org.yaml:snakeyaml
Description
Uncontrolled Resource Consumption in snakeyaml The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 1.31 | ||
debian 12 | 1.31-1 | ||
debian 13 | 1.31-1 | ||
debian 14 | 1.31-1 | ||
rpm rhel7 | - | - | |
rpm rhel8 | 0:0.12.0-8.el8_6 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.